CVE-2025-34218·Docker vulnerability
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA/SaaS deployments) expose internal Docker containers through the gw Docker instance. The gateway publishes a /meta endpoint which lists every micro‑service container together with version information. These containers are reachable directly over HTTP/HTTPS without any access‑control list (ACL), authentication or rate‑limiting. Consequently, any attacker on the LAN or the Internet can enumerate all internal services and their versions, interact with the exposed APIs of each microservice as an unauthenticated user, or issue malicious requests that may lead to information disclosure, privilege escalation within the container, or denial‑of‑service of the entire appliance. The root cause is the absence of authentication and network‑level restrictions on the API‑gateway’s proxy to internal Docker containers, effectively turning the internal service mesh into a public attack surface. This vulnerability has been identified by the vendor as: V-2024-030 — Exposed Internal Docker Instance (LAN).
- Severity
- critical
- Software
- Docker
- Fixed in
- 22.0.1049
- Published
- 2025-09-29
Affected versions
Until: 22.0.1049
Fixed in: 22.0.1049
How to fix this CVE
Upgrade Docker to version 22.0.1049 or later to patch the exposed internal Docker instance vulnerability. This critical issue allows unauthenticated attackers to enumerate microservices, access internal APIs, and potentially escalate privileges or cause denial-of-service. Ensure all Vasion Print Virtual Appliance and SaaS deployments are updated immediately, and implement network-level access controls to restrict direct communication with internal container endpoints.
sudo dnf update docker-ce docker-ce-cli containerd.ioDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
GET /meta HTTP/1.1|POST /meta HTTP/1.1|GET /api/v[0-9]+/services HTTP/1.1|HTTP response containing internal microservice container names, versions, or 'gw' Docker instance identifiers without 401/403 response codesWAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Block unauthenticated HTTP requests to the /meta and /api/* endpoints on the appliance gateway. Implement IP-based access controls to restrict gateway access to trusted networks only. Require Bearer token or API key authentication for all gateway proxy requests to internal microservices.How to check if you are affected
- Check installed Docker version: docker --version or dpkg -l | grep docker-ce (Ubuntu/Debian) or rpm -q docker-ce (RHEL/CentOS)
- Verify the gateway endpoint exposure: curl -s http://<appliance-ip>:8080/meta | jq . (or without jq) to see if internal microservice containers are enumerated
- Search Docker container logs for unauthorized API requests: docker logs $(docker ps -q) | grep -E '(unauthenticated|401|403|unauthorized)' to identify exploitation attempts
- Confirm patch applied: docker --version should report 22.0.1049 or higher, and the /meta endpoint should require authentication or be unavailable
Indicators of compromise
- GET /meta (unauthenticated)
- HTTP response body containing 'container.*version' or 'microservice' JSON objects
- Direct internal service endpoint requests (e.g., http://<gw-ip>:8080/service-name/api)
- User-Agent scanning for reconnaissance tools accessing /meta endpoint
FAQ
What is CVE-2025-34218?
This vulnerability exposes the internal Docker container mesh in Vasion Print Virtual Appliances through an unauthenticated gateway endpoint (/meta) that lists all microservices and their versions. Attackers can directly interact with internal APIs without authentication, leading to information disclosure, privilege escalation, or appliance-wide denial-of-service.
Is CVE-2025-34218 being actively exploited?
No, this vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits have been released, though researchers have published proof-of-concept details. Organizations should still treat this as critical due to its CVSS 9.8 score and ease of exploitation.
What versions of Docker are affected by CVE-2025-34218?
Vasion Print Virtual Appliance Host versions prior to 22.0.1049 and Application versions prior to 20.0.2786 are vulnerable. All earlier Docker-based deployments of Vasion Print should be upgraded immediately.
How do I check if my server is vulnerable to CVE-2025-34218?
Run: docker --version to check your Docker version (should be 22.0.1049 or higher). Then test: curl -s http://localhost:8080/meta or curl -s http://<appliance-ip>/meta to see if the gateway endpoint exposes internal microservices without authentication.
Does Defensia detect CVE-2025-34218?
Yes — Defensia's CVE advisory scanner compares installed Docker package versions against the NVD database. If Docker is installed on a monitored server, CVE-2025-34218 will appear in your dashboard with remediation steps and version-specific upgrade commands.
Related Docker CVEs
References
- https://help.printerlogic.com/saas/Print/Security/Security-Bulletins.htm
- https://help.printerlogic.com/va/Print/Security/Security-Bulletins.htm
- https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-exposed-docker-instances
- https://www.vulncheck.com/advisories/vasion-print-printerlogic-exposed-internal-docker-instance
- https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-exposed-docker-instances
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-34218. Free for 1 server.
Get started free